Skip to content

subscribeToShapes

subscribeToShapes(options, claims, requests, now): Promise<SubscribeResult>

Defined in: packages/server/src/circuits/subscribe.ts:280

Subscribe to a batch of shapes: compile each against the registry, check entitlement, register it with the engine, and mint ONE token covering all of them.

A shared-tier shape FANS OUT: one stream per scope the subject holds, so K requested shapes yield however many grants their entitlements come to. Expansion happens here rather than on the client because this is the side holding the entitlement set — see SubscriptionRequest.

A partial result rather than an all-or-nothing one. A subject holding K scopes at boot may legitimately have lost one of them, and failing the whole batch on that would deny them the K-1 they still hold — so a denial is reported per subscription and the rest proceed.

That partiality covers AUTHORIZATION only. An engine that cannot answer — degraded, unreachable — is not a denial and must never be reported as one: a client told “not entitled” truncates that scope and unsubscribes, so reporting an outage that way would turn a transient engine fault into client-side data loss. Engine failures propagate, and the route answers 503.

An entitlement set that is not ready joins it. It is the same shape of failure — a dependency that cannot answer right now — and the client’s response to a denial is the same clear, so it propagates as EntitlementsUnavailableError and the route answers 503 too. What stays a denial is the set being absent altogether: that is a deployment’s permanent configuration.

Entitlement is checked HERE as well as at the edge, and the duplication is deliberate: this is what stops a shape being created and a capability minted for a scope the subject never held. The edge’s check bounds how long an already-minted one keeps working.

SubscribeOptions

{[key: string]: unknown; app_metadata?: {[key: string]: unknown; roles?: string[]; }; sub?: string; } | null

readonly SubscriptionRequest[]

number

Promise<SubscribeResult>